CVE-2024-6678
Sept. 18, 2024, 7:14 p.m.
Tags
CVSS Score
Products Impacted
Vendor | Product | Versions |
---|---|---|
gitlab |
|
|
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.
Weaknesses
CWE-290
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE ID: 290Date
Published: Sept. 12, 2024, 7:15 p.m.
Last Modified: Sept. 18, 2024, 7:14 p.m.
Source
cve@gitlab.com
CPEs
Type | Vendor | Product | Version | Update | Edition | Language | Software Edition | Target Software | Target Hardware | Other Information |
---|---|---|---|---|---|---|---|---|---|---|
a | gitlab | gitlab | / | / | / | / | community | / | / | / |
a | gitlab | gitlab | / | / | / | / | enterprise | / | / | / |
a | gitlab | gitlab | / | / | / | / | community | / | / | / |
a | gitlab | gitlab | / | / | / | / | enterprise | / | / | / |
a | gitlab | gitlab | / | / | / | / | community | / | / | / |
a | gitlab | gitlab | / | / | / | / | enterprise | / | / | / |
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
Exploitability Score
Impact Score
Base Severity
HIGHCVSS Vector String
The CVSS vector string provides an in-depth view of the vulnerability metrics.
View Vector StringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H